Improper Authentication in pgAdmin - CVE-2024-4215

 

Improper Authentication in pgAdmin - CVE-2024-4215

Published: July 8, 2024


Vulnerability identifier: #VU93853
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-4215
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass multi-factor authentication.

The vulnerability exists due to incorrect implementation of multi-factor authentication. A remote attacker with knowledge of valid credentials can bypass multi-factor authentication and gain unauthorized access to the application.


Affected software

pgAdmin
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Fedora
python-libgravatar
pgadmin4
system-user-pgadmin
pgadmin4-doc
pgadmin4-desktop
pgadmin4-cloud
pgadmin4-web-uwsgi

How to mitigate CVE-2024-4215

Install updates from vendor's website.

pgAdmin - update to 8.6
python-libgravatar - update to 1.0.4-1.fc40
pgadmin4 - update to 8.5-150600.3.3.1
system-user-pgadmin - update to 8.5-150600.3.3.1
pgadmin4-doc - update to 8.5-150600.3.3.1
pgadmin4-desktop - update to 8.5-150600.3.3.1
pgadmin4-cloud - update to 8.5-150600.3.3.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.3.1
pgadmin4 - update to 8.6-1.fc40

External References

Related Security Bulletins